CISA
Coverage of CISA in the Nexus archive.
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical flaw affecting Ray to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. This vulnerability can potentially trigger a browser-based RCE. Ray is described as an open-source, Python-native distributed computing framework used for scaling AI and machine learning workloads.
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed that ransomware gangs have begun abusing a high-severity vulnerability in Microsoft SharePoint. This remote code execution flaw has been actively exploited since early July.
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
CISA added a high-severity vulnerability (CVE-2026-18577) in N-able N-central to its KEV catalog due to active exploitation. The flaw stems from incomplete patching of CVE-2026-18556, both rated with a CVSS score of 8.2.
- Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
Georgia and Michigan reported cyberattacks on water systems, with the FBI investigating incidents in at least seven U.S. states. While Iran-backed hackers are suspected, no official attribution has been made, and no operational disruptions were reported in either state.
- CISA Alert: Water Sector PLC Targeting
CISA has issued an alert regarding targeting of water sector Programmable Logic Controllers (PLCs). The article is sourced from the Censys blog and includes a Hacker News comments link with no user discussions.
- CISA warns of spike in attacks on water systems as Minnesota incidents probed
CISA issued a public alert warning of increased cyberattacks on water systems and advised removing exposed PLCs and operational technology from the internet. The alert follows investigations into incidents in Minnesota.
- Sweeping cyberattack on water systems in multiple states has officials on edge
Hackers have launched a coordinated cyberattack on water systems in multiple US states, prompting boil-water advisories and manual system operations. US officials, including CISA, FBI, and EPA, are working to secure facilities, with Iran suspected as a potential culprit but no formal attribution confirmed.
- CISA issues recommendations to federal agencies on open-source software security
CISA issued a guidebook for federal agencies on managing open-source software security risks, covering topics like patching and open-source AI models. The guidance, prompted by executive orders from Presidents Biden and Trump, addresses recent OSS attacks and emphasizes assessing code quality and security. An open-source security expert praised the guidance for its practical approach to using open-source software safely.
- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
CISA added a zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software to its KEV catalog due to active exploitation. The flaw, CVE-2026-20316 (CVSS score: 5.3), allows unauthenticated remote attackers to log in and potentially expose sensitive data.
- Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
Huntress researchers identified a credential stuffing campaign targeting SonicWall VPN and firewall accounts, compromising 30 organizations in two days and 92 accounts in 41 hours. The attacks, which ceased abruptly, may involve pre-positioning for future intrusions, with attackers using valid credentials obtained through unknown means. SonicWall is investigating, while CISA has cataloged 17 exploited vulnerabilities in its products since 2021, including those linked to ransomware campaigns.
- CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems during cyberattacks or major disruptions. The advice focuses on protecting essential systems from cyber threats.
- Outdated VPNs should be purged from federal agencies, senator says
Senator Ron Wyden urges CISA, OMB, and NIST to lead a federal initiative to eliminate outdated virtual private networks (VPNs) from U.S. government agencies. The call aims to address security vulnerabilities associated with obsolete technology.
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to steal emails, password data, and two-factor authentication recovery codes. The attack, which targeted the last 90 days of email and an organization's directory, was disclosed by the NSA, CISA, and partner agencies.
- Why blocking AI models won’t stop the cyber threats they create
2026 sees AI-powered cyberattacks becoming a reality as new models rival human hackers, challenging existing cybersecurity infrastructure. Export controls on AI models like Anthropic’s Mythos and OpenAI’s GPT-5.5 are temporary solutions, as competitors rapidly develop equivalent capabilities. The article emphasizes the need for increased defense investment, noting that private AI companies are filling gaps left by reduced federal agency resources but lack the mandate to secure national systems comprehensively.
- CISA urges immediate action on actively exploited Fortinet flaws
CISA has ordered government agencies to urgently patch two actively exploited vulnerabilities in Fortinet's FortiSandbox threat detection platform. The vulnerabilities are being exploited, prompting immediate action.
- Trump alleges vast conspiracy to commit and cover up election fraud
President Trump accused U.S. intelligence agencies of covering up Chinese efforts to compromise the 2020 election, citing released White House documents alleging Beijing's acquisition of 220 million voter files. He claimed intelligence briefings omitted significant reports about Chinese election targeting, including attempts to manufacture illegal ballots for Joe Biden.
- CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has mandated federal agencies to address a critical vulnerability in Oracle's E-Business Suite financial application by Saturday due to ongoing attacks exploiting the flaw.
- Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
CISA added two critical Joomla extension vulnerabilities (iCagenda and Balbooa Forms) to its KEV catalog, both rated with a CVSS score of 10. Attackers exploited these flaws to upload malicious PHP code, enabling remote server control. Patches are available, but exploitation continues on unpatched sites.
- CISA warns of actively exploited RCE flaws in Joomla extensions
CISA is warning about actively exploited remote code execution (RCE) vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla. Attackers are leveraging these flaws to achieve RCE through arbitrary file uploads.
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
CISA added two maximum-severity vulnerabilities in iCagenda and Balbooa Joomla extensions to its KEV catalog, citing reports of zero-day exploitation. Both flaws, rated 10.0 on the CVSS scale, are being actively exploited.
- US cyber agency CISA had to build its incident playbook during the incident, agency reveals
CISA had to develop its incident playbook during a security incident, as the agency acknowledged missing an opportunity to create a response plan in advance.
- CISA looks to remedy ailments from big May credential leak
CISA responded to a May 2023 credential leak by improving protections for sensitive materials, enhancing vulnerability reporting processes, and developing incident response plans. The leak, involving exposed Amazon AWS GovCloud keys on GitHub, led to no customer data exposure, and CISA implemented measures like endpoint monitoring and secret rotation. A security researcher praised CISA’s transparency in acknowledging both successful and flawed aspects of its response.
- CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents, setting a deadline of Friday.
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA added four actively exploited vulnerabilities to its KEV catalog, including a critical path traversal flaw in Adobe ColdFusion (CVE-2026-48282) that could enable arbitrary code execution. The other flaws affect Joomla and Langflow, with all vulnerabilities being actively exploited.
- The Download: your stake in OpenAI, and the Treasury’s AI warning
Sam Altman proposes a 5% government stake in OpenAI, offering $320 per household. The US Treasury compares the AI market to the dotcom bubble, while Samsung reports record profits from AI chips and Illinois enacts a strong frontier AI law.
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
CISA added a high-severity remote code execution vulnerability (CVE-2026-45659) in Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog due to active exploitation. The flaw, rated with a CVSS score of 8.8, stems from deserialization of untrusted data.
- Citrix patches a new NetScaler flaw with echoes of CitrixBleed
Citrix disclosed six vulnerabilities in NetScaler ADC and Gateway, including a high-severity memory disclosure flaw (CVE-2026-8451) linked to the CitrixBleed vulnerability class. Researchers at watchTowr and others identified the flaws, which involve memory management issues and require patching and configuration adjustments to mitigate risks.
- CISA: Windows BlueHammer flaw now exploited by ransomware gangs
CISA confirmed that ransomware gangs are exploiting a Microsoft Defender privilege escalation vulnerability named BlueHammer, which was previously used in zero-day attacks. The flaw allows attackers to escalate privileges, potentially leading to system compromises.
- FBI: Russian hackers now target Signal backup recovery keys
The FBI and CISA warn that Russian intelligence-linked hackers are targeting Signal users through a phishing campaign to steal Backup Recovery Keys, enabling access to historical messages. The campaign has evolved to focus on these keys, which are critical for securing Signal backups.
- CISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA has issued an urgent deadline for federal agencies to patch a vulnerability in Cisco Unified Communications Manager Server that is currently being exploited in attacks.
- FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
The FBI and CISA have updated their warning about Russian hackers phishing Signal accounts to obtain backup recovery keys, allowing attackers to access message history and take over accounts. The keys remain valid indefinitely once compromised.
- DHS chief says president has met with potential CISA nominee; agency plans to hire 600
Homeland Security Secretary Markwayne Mullin stated that the president has met with a potential nominee for the CISA director position. The agency plans to hire 600 additional staff once a new director is confirmed. The White House has not yet announced the nominee.
- Why patch directives only go so far
CISA issued an emergency directive for CVE-2026-50751, a critical authentication bypass vulnerability in Check Point Remote Access VPN, after exploitation began in May. Qilin ransomware affiliates exploited the flaw to breach organizations globally, using techniques like Rclone and Tox protocol for data exfiltration and command-and-control. The vulnerability highlights structural flaws in perimeter-dependent security architectures, where compromised security devices inherit trusted authority.
- Open-source security is posing challenges governments can’t easily solve
An increase in cyberattacks on open-source software highlights challenges in securing publicly available code, with experts citing underinvestment and maintenance issues. Governments under different administrations have had mixed impacts, while companies also face criticism for insufficient responsibility. Project Glasswing identified thousands of vulnerabilities in open-source projects, but only a small fraction have been patched.
- Former CISA Director Chris Krebs calls intelligence community's AI warning "pretty alarming"
An international alliance warns that advanced artificial intelligence models could soon overwhelm cybersecurity systems for governments and businesses. Chris Krebs provides analysis on the issue.
- Intel agencies: Frontier AI models will reshape cybersecurity faster than expected
Intelligence agencies from the Five Eyes alliance (US, Canada, UK, Australia, New Zealand) warn that advanced AI models capable of significantly impacting cybersecurity are months away from public availability. These models, including Anthropic's Fable 5 and OpenAI's Daybreak, could transform offensive and defensive cyber capabilities rapidly, exploiting weaknesses like legacy systems and slow patching. The agencies emphasize that older AI models and open-source variants already pose risks, with newer models quickly becoming accessible as development accelerates.
- CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks.
- CISA warns Fortinet users to secure devices after FortiBleed leak
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Fortinet users to secure their devices following the 'FortiBleed' data leak, which exposed nearly 74,000 firewall and VPN credentials. The incident highlights the need for immediate action to protect affected systems.
- Warner warns of CISA cuts, staffing gaps in letter to acting chief
Warner warned of potential cuts and staffing gaps at CISA in a letter to DHS Secretary Markwayne Mullin, urging the Department of Homeland Security to prioritize the agency and fund the MS-ISAC.
- CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
CISA added a vulnerability in LiteSpeed cPanel Plugin to its KEV catalog, requiring FCEB agencies to fix it by June 18, 2026. The flaw, CVE-2026-54420 (CVSS score 8.5), involves privilege escalation exploited for root access.